PoC Exploit Publicly Disclosed: Windows ‘libarchive’ Flaw Leaks NetNTLMv2 Hashes
ID: 2f0cd94a-159d-5053-8c20-9332968c42ed
STIX ID: report--2f0cd94a-159d-5053-8c20-9332968c42ed
Feed Name: securityonline.info
Threat Score
Security researchers disclosed CVE-2025-59284 in Windows' libarchive handling: a specially crafted tar with hardlinks can force the OS to resolve a UNC path during archive extraction or file open, causing NetNTLMv2 authentication requests to be sent to attacker-controlled servers and leaking hashes; a public PoC exists and Microsoft’s patch currently displays a warning dialog that may not prevent exploitation if users accept it.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
